TRUST / OPERATING STANDARDBOUNDARY BEFORE CAPABILITY

Trust is an operating condition.

Private infrastructure is credible only when its authority, evidence and recovery path can be examined. We define those conditions before deployment and operate against them after acceptance.

SCOPE / READ THIS FIRST

Controls are deployment-specific. Claims should be too.

This page describes the Kastral operating baseline. Final controls, locations, responsibilities, service levels and evidence are recorded for each engagement. We do not imply certifications that have not been independently awarded.

SIX CONTROL DOMAINSDESIGN / FIELD / PROVE / OPERATE
01

Boundary and tenancy

A dedicated environment for one organisation, with deployment location, network paths and administrative boundaries defined before fielding.

02

Identity and authority

Customer identity integration, least-privilege access, explicit workload authority and human approval where actions carry consequence.

03

Data protection

Private transport, controlled storage, permission-aware access and retention conditions established around the organisation's material.

04

Model governance

Approved runtimes, replaceable models, workload evaluations and controlled change instead of an irreversible provider dependency.

05

Operations and evidence

Monitoring, patching, security events, model and version records, operational logs and an accountable response path.

06

Continuity and exit

Backups, restore testing, recovery responsibilities, portable records and exit conditions designed before acceptance.

ASSURANCE EVIDENCE

Prepared for technical and procurement diligence.

RESPONSIBLE DISCLOSURE

Found a security issue?

Email security@kastral.eu with “Security disclosure” in the subject. Do not include live credentials, personal data or exploit sensitive production systems. We will acknowledge a credible report and coordinate remediation privately.